WordPress

How to clean malware from a hacked WordPress site

If your site shows spam pages, redirects visitors, or Google flags it, it may be infected. Act quickly and calmly.

  1. Take the site offline or into maintenance mode to protect visitors.
  2. Change all passwords — WordPress admin, hosting, FTP and database.
  3. Scan with a security plugin such as Wordfence or MalCare and let it remove infected files.
  4. Update WordPress core, all themes and plugins, and delete any you do not recognise or use.
  5. Restore a clean backup from before the infection if you have one — our DirhamVault off-site backups keep dated copies.

After cleaning, install a firewall, enable 2FA, and request a review in Google Search Console to clear any warning. Malware usually gets in through outdated plugins or weak passwords, so keeping everything updated prevents a repeat.

Our UAE-based team is available 24/7 and can help investigate and restore your site. Contact WhatsApp +971 58 553 6767 or support@dirhamaday.ae straight away if you suspect a hack.

Still need a hand? Our UAE-based team is here 24/7.

Related articles

How to install WordPress with 1-clickHow to log in to your WordPress dashboard (wp-admin)How to choose and install a WordPress themeEssential plugins for a new WordPress siteHow to update WordPress, themes and plugins safely